Publishing through the portal
In the Business Portal every record starts as a draft. A draft is private, editable by anyone at your business with the right role, and never served. Publishing is a save: the person reviews what will be published and seals it with their passkey.
Drafts
Section titled “Drafts”- Every record type has drafts: products, the Business & Brand file, events, jobs, updates, and your AI policy.
- Validation runs as you edit and again on save, with every reason at once: the same rules a push meets.
- The diff since the last publish is on the save screen, so what you seal is what you have looked at — including anything a colleague changed.
- On a verified business, editing a draft needs a recently confirmed sign-in, so a stolen email session cannot plant a change for someone else to seal unseen.
The save
Section titled “The save”On save, your browser builds the draft’s canonical form — UTF-8, keys sorted, no extra whitespace, decimal quantities (money included) as strings — hashes it, and your passkey signs it (Sealing with a passkey). MasterDB checks that the bytes it received are exactly that canonical form and hash to what you sealed, stores exactly those bytes, and refreshes the draft from them. A colleague’s edit made between your review and your save can never be what gets sealed.
Who may save what depends on your role: a catalogue manager’s seal is accepted for products and refused for the Business & Brand file. The role in force at the moment of sealing is recorded with the record.
After a save
Section titled “After a save”- The record is live in every region within seconds. The portal shows where it is live.
- Every owner and admin receives a confirmation by email that names the person who published, with a plain link to the record in the portal — never a sign-in link. Each owner and admin chooses how: one person’s changes grouped into one email every 10 minutes (the default), an email each time, a daily summary, or off (Choosing which emails you get). An unexpected confirmation is how a compromised account or a compromised portal is noticed within minutes.
- A later save publishes a new version of the same record; the history stays.
Withdrawing and deleting
Section titled “Withdrawing and deleting”Withdrawing takes a record out of serving everywhere; its history stays. Deleting removes it: its bytes are purged within 30 days, and MasterDB keeps only its fingerprints — its hashes and log entries — so it can still say when a record with that hash was live, but not what it said. Both are sealed actions, like a save.